Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
* HanIRCÀÇ #coffeenix ¹æ
[ Àåºñ ¹× ȸ¼± ÈÄ¿ø ]
HOME > º¸¾È(security) > ¹ÙÀÌ·¯½º(virus) / ¿ú / ¹é½Å µµ¿ò¸»
°Ë»ö : »çÀÌÆ® WHOIS À¥¼­¹ö Á¾·ù


  ¸ÞÀÏ ¹ÙÀÌ·¯½º Â÷´Ü AntiVir Milter FAQ (¹®Á¦ÇØ°áÆí) ÀÛ¼ºÀÏ : 2003/09/06 02:20
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 7071
          [ ÀÌÀüÈ­¸é / ¼öÁ¤ ]   ºñ¹Ð¹øÈ£ :     Àμâ¿ë È­¸é
      ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2003.09.05(±Ý)

    ÀÌ ±ÛÀº Àü¿¡ ½è´ø "¸ÞÀÏ·Î µé¾î¿À´Â ¹ÙÀÌ·¯½º Â÷´Ü AntiVir Milter ¼³Ä¡ ¹× ¿î¿µ"
    ÀÇ ¿¬Àå¼±»ó¿¡ ÀÖ´Â ±ÛÀÔ´Ï´Ù.

    Antivir Milter ¼³Ä¡´Â °£´ÜÇÕ´Ï´Ù. ±×·¯³ª
    - ¼³Ä¡ ȯ°æÀÌ ´Ù¾çÇÏ°í
    - Çѱ۷ΠµÈ ¹®¼­¸¦ ã±â°¡ ½±Áö¾Ê¾Æ¼­
    ¼ø¼­´ë·Î Çߴµ¥ ¹®Á¦ ¹ß»ýÇÒ ¶§ ÇØ°áÃ¥ ã±â°¡ ½±Áö ¾Ê¾ÒÀ» °Ì´Ï´Ù.

    Àú¿¡°Ô Á÷Á¢ Áú¹®ÇÑ °Í°ú KLTP¸¦ ÅëÇØ Áú¹®ÇÑ °ÍÀ» Á¤¸®ÇÑ °Í¿¡ ºÒ°úÇÕ´Ï´Ù.
    AntivirÅøÀÇ Àü¹®°¡µµ ¾Æ´Ñµ¥ ¿©·¯ Áú¹®À» ¹Þ´Ùº¸´Ï ¿©±â±îÁö(?) ¿À°Ô µÆ½À´Ï´Ù.
    ¹®Á¦ ÇØ°á¿¡ µµ¿òÀÌ µÇ±â¸¦...

    Q1) ¼Ö¶ó¸®½º¿¡¼­µµ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï±î?
    -----------------------------------------------------------------------

    A1) Antivir Milter´Â Linux, FreeBSD, OpenBSD¿ë¸¸ ÀÖ½À´Ï´Ù.

    Q2) Qmail¿¡¼­´Â Antivir Milter »ç¿ëÀº?
    -----------------------------------------------------------------------

    A2) Antivir Milter´Â sendmail¿ëÀÔ´Ï´Ù.

    sendmailÀÇ Milter API¸¦ ÀÌ¿ëÇؼ­ µ¿ÀÛÇÕ´Ï´Ù.
    ±×·¯³ª qmail¿¡¼­ ÀüÇô »ç¿ëÇÒ ¼ö ¾ø´Â °ÍÀº ¾Æ´Õ´Ï´Ù.
    AntiVir MailGate ¶ó´Â°Ô ÀÖ½À´Ï´Ù.

    AntiVir MailGate for linux, freebsd, openbsd
    http://www.hbedv.com/download/download.htm

    sendmailÀº ¹°·Ð qmail±îÁö Áö¿øÇÕ´Ï´Ù.
    qmailÀÌ ¸ÞÀÏÀ» ¹ÞÀ¸¸é mailgate¿¡ ³Ñ°Ü¼­ °Ë»ç ÈÄ¿¡ ´Ù½Ã qmailÀÌ ¹Þ´Â ÇüÅ·Î
    󸮸¦ ÇÕ´Ï´Ù.
    linux¿¡¼­ ¼³Ä¡´Â avinstall.pl¶ó´Â ÀνºÅç·¯°¡ ÀÖÀ¸´Ï ½±°Ô °¡´ÉÇÕ´Ï´Ù.
    ¼³Á¤Àº INSTALL.qmailÀ» »ìÆ캸±â ¹Ù¶ø´Ï´Ù.
    qmailÀ» µÎ°³ ¶ç¿ì°í À̸®Àú¸® ³Ñ°Ü ¹Þ´Â °úÁ¤ÀÌ ÇÊ¿äÇÕ´Ï´Ù.


    Q3) ¼³Á¤ÈÄ sendmail ½ÇÇà½Ã¿¡ unknown configuration line "Xavmilter...  ¿¡·¯
    -----------------------------------------------------------------------

    /etc/rc.d/init.d/sendmail restart ¿¡¼­

    unknown configuration line "Xavmilter, S=inet:3333@localhost, F=R,
    T=S:10m;R:10m;E:10m"
    554 /etc/sendmail.cf: line 1217: readcf: unknown option name InputMailFilters

    ¿Í °°Àº ¿¡·¯°¡ ¹ß»ýÇß½À´Ï´Ù.

    A3) SendmailÀÌ Milter ±â´ÉÀ» Æ÷ÇÔÇÏÁö ¾Ê°í ÄÄÆÄÀϵǾî ÀÖ½À´Ï´Ù.

    Milter API´Â sendmail 8.10.x ÀÌ»óÀÌ¸é °¡´ÉÇϳª ÄÄÆÄÀÏÇÒ ¶§ Á¦¿Ü(default·Î
    ÄÄÆÄÀÏÇϸé Á¦¿ÜµÊ)µÈ °É·Î ÆǴܵ˴ϴÙ.

    ·¹µåÇÞ 7.2 À̻󿡼­´Â Sendmail Milter API¸¦ ¾µ ¼ö ÀÖµµ·Ï ÄÄÆÄÀϵǾî ÀÖ½À´Ï´Ù.
    ÀÌÀü ¹èÆ÷ÆÇ ¹öÀüÀÌ´õ¶óµµ ÃÖ±Ù ¾÷µ¥ÀÌÆ®µÈ sendmail rpmÀ» ¼³Ä¡Çϸé ÇØ°áµË´Ï´Ù.
    ·¹µåÇÞÀ» »ç¿ëÇÏ½Ã¸é ´ÙÀ½ ÁÖ¼Ò¿¡¼­ ¹Þ¾Æ¼­ ¼³Ä¡Çϼ¼¿ä.

    https://rhn.redhat.com/errata/RHSA-2003-120.html
    À§ rpmÆÐÅ°Áö´Â sendmail 8.11.6ÀÔ´Ï´Ù.

    ¼³Ä¡´Â ¾î¶»°Ô ÇÏ´ÂÁö ¾Æ½ÃÁÒ?
    rpm -Fvh sendmail-8.11.6-??.??.????.rpm
    rpm -Fvh sendmail-cf-8.11.6-??.??.????.rpm
    rpm -Fvh sendmail-devel-8.11.6-??.??.????.rpm
    rpm -Fvh sendmail-doc-8.11.6-??.??.????.rpm

    ÀÌ·¡µµ Àß ¾ÈµÇ¸é Á÷Á¢ ÄÄÆÄÀÏÇØ¾ß ÇÕ´Ï´Ù.
    ÄÄÆÄÀÏÇÏ°Ô µÇ¸é Build Àü¿¡ devtools/Site/site.config.m4 ÀÛ¼ºÇÏ°í
    ¼³Ä¡ ÈÄ¿¡ sendmail.cf ¸¸µå´Â °úÁ¤µéÀÌ ÇÊ¿äÇÕ´Ï´Ù.

    Q4) AntiVir Milter½ÇÇà½Ã can't initialize scan engine ¿¡·¯°¡ ¹ß»ý
    -----------------------------------------------------------------------

    A4) ¿©·¯°¡ÁöÀÇ °æ¿ì°¡ ÀÖ½À´Ï´Ù.

      °¡Àå ¸ÕÀú /usr/lib/Antivir/antivir¸¦ ½ÇÇàÇغ¸¼¼¿ä.

      Antivir Milter´Â ¸ÞÀÏ ¹ÙÀÌ·¯½º °Ë»ç¸¦ À§ÇØ antivir¸¦ È£ÃâÀ» ÇϹǷÎ
      antivir°¡ Á¤»óÀûÀ¸·Î ½ÇÇàÇÒ ¼ö ¾ø´Â ȯ°æÀ̸é À§ÀÇ ¿¡·¯¸¦ ¹ß»ýÇÏ°í Á¾·áÇÕ´Ï´Ù.

      1) /var/tmp, /tmpÀÇ Æ۹̼ÇÀÌ 1777(rwxrwxrwt)°¡ ¾Æ´Ñ °æ¿ì

         chmod 1777 /var/tmp/ ¿Í °°ÀÌ Æ۹̼ÇÀ» º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù.

      2) ¶óÀ̼¾Æ® ÆÄÀÏ(hbedv.key, avmgate.key)ÀÌ ¼³Ä¡¾ÈµÇ¾î Àְųª
         uucp »ç¿ëÀÚ°¡ ÀÐÀ» ¼ö ¾ø´Â °æ¿ì

         ÀÌ·² ¶§ Á÷Á¢ ½©¿¡¼­ antivir½ÇÇàÇϸé DEMO mode¶ó°í ³ª¿É´Ï´Ù.

         # antivir
         AntiVir / Linux Version 2.0.8-1
         Copyright (C) 1994-2003 by H+BEDV Datentechnik GmbH.
         All rights reserved.

         Loading /usr/lib/AntiVir/antivir.vdf ...

         AntiVir is running in DEMO mode.
         ... »ý·« ...

         ¶óÀ̼¾½º¸¦ ¹ÞÁö ¾Ê¾Ò´Ù¸é http://www.hbedv.com/private/ ¿¡¼­
         ¹Þ¾Æ ¼³Ä¡Çϼ¼¿ä. Æ۹̼ÇÀº Á¦ ±ÛÀ» Àо¸é µË´Ï´Ù.

      3) /usr/lib/Antivir/antivir°¡ ÀÓÀÇ·Î º¯°æµÈ °æ¿ì

        antivir´Â ´Ù¸¥ ¹é½ÅÇÁ·Î±×·¥Ã³·³ ÀÚü Áø´Ü±â´ÉÀÌ ÀÖ½À´Ï´Ù.
        ÀÚ½ÅÀÌ ÀÓÀÇ·Î º¯°æµÆ´Ù°í ÆǴܵǸé
        211 ¿À·ù(Programm aborted, because the self check failed)¸¦ ¹ß»ýÇϸç
        Á¾·áÇÕ´Ï´Ù.
        ÀÌ·±°æ¿ì´Â µå¹É°ÚÁö¸¸ Linux/OSF-8759 ¿ú ¹ÙÀÌ·¯½º µî¿¡ °É¸° °æ¿ì
        ½ÇÇà ÆÄÀÏÀÌ º¯°æµÇ¹Ç·Î Àú·± Çö»óÀÌ »ý±æ ¼ö ÀÖ½À´Ï´Ù.

      4) À§ÀÇ 3°¡Áö´Ù ÇØ´çÀÌ ¾ÈµÇ´Â °æ¿ì

        /usr, /usr/lib, /var µîÀÇ µð·ºÅ丮ÀÇ Æ۹̼ÇÀ» È®ÀÎÇϼ¼¿ä.
        Antivir Milter´Â µðÆúÆ®·Î uucp:uucp »ç¿ëÀÚ:±×·ìÀ¸·Î ½ÇÇàµË´Ï´Ù.
        µû¶ó¼­ /usr µð·ºÅ丮°¡ ¸¸¾à 711(rwx--x--x)¶ó¸é ½ÇÇàÇÒ ¼ö ¾ø½À´Ï´Ù.
        755(rwxr-xr-x)·Î º¯°æÇغ¸¼¼¿ä.

    Q5) AntiVir Milter½ÇÇà½Ã chdir to "/var/spool/avmilter" failed - exiting!
        ¿¡·¯ ¹ß»ý
    -----------------------------------------------------------------------

    A5) Antivir Milter´Â ½ºÇ®µð·ºÅ丮ÀÇ ¼ÒÀ¯ÀÚ¿Í Æ۹̼ÇÀ» °Ë»çÇÕ´Ï´Ù.
        ¸¸¾à 700(rwx------)ÀÌ ¾Æ´Ï´Ù¸é À§ÀÇ ¿¡·¯¸¦ ¹ß»ýÇϸç Á¾·áÇÕ´Ï´Ù.

    chown -R uucp:uucp /var/spool/avmilter
    chmod -R 700       /var/spool/avmilter

    ·Î º¯°æÇϸé ÇØ°áµË´Ï´Ù.

    Q6) sendmail.cf ¼³Á¤ºÎºÐ¿¡¼­
        Xavmilter, S=inet:3333@localhost, F=R, T=S:10m;R:10m;E:10m
        O InputMailFilters=avmilter

        ¸¦ sendmail.cf ³» ¾îµð¿¡ À§Ä¡ÇØ¾ß Çϳª¿ä?
    -----------------------------------------------------------------------

    A6) À§Ä¡´Â »ó°ü¾øÀ¸³ª, ¿É¼Ç ¼³Á¤ÇÏ´Â ºÎºÐÀÌ ÀÖ½À´Ï´Ù.
    ±× ¼³Á¤ ºÎºÐ¿¡ µÎ´Â°Ô ÁÁÀ» °Í °°½À´Ï´Ù.

    À̸¦ Å׸é
    O AliasFile=/etc/aliases
    ¿Í °°ÀÌ µé¾î ÀÖ´Â ºÎºÐ ±Ùó¿¡.

    Q7) /var/log/messages¿¡ ½×ÀÌ´Â ·Î±×¸¦ ´Ù¸¥ÂÊÀ¸·Î µ¹¸®°í ½ÍÀºµ¥ °¡´ÉÇϳª¿ä?
    -----------------------------------------------------------------------

    A7) Antivir Milter¸¦ ÅëÇØ ³²°ÜÁø ·Î±×¸¦ ´Ù¸¥ °÷À¸·Î ¿Å±â´Â ¼³Á¤Àº ¾ø½À´Ï´Ù.
       (Áö±Ý±îÁö È®ÀÎÇѹٷÎ)

    ±×·¯³ª ¸ÞÀÏ°ú´Â ¹«°üÇÏ°Ô ½©»ó¿¡¼­ antivir¸¦ ½ÇÇàÇÏ¿© ³²±â´Â ·Î±×´Â °¡´ÉÇÕ´Ï´Ù.
    ¼³Á¤ ÆÄÀÏÀÎ /etc/antivir.conf ¸¦ ¼öÁ¤ÇÕ´Ï´Ù.

    LogTo /var/log/antivir.log
    SyslogFacility local1
    SyslogPriority debug

    1¹ø°ÁÙ = /var/log/antvir.log¿¡ ·Î±×°¡ ³²µµ·Ï ÇÕ´Ï´Ù.
    ´ÙÀ½ 2ÁÙ= messages¿¡ ·Î±×°¡ ³²Áö ¾Êµµ·Ï ÇÕ´Ï´Ù. (ÀÓ½ÃÀûÀÎ ¹æ¹ý)

    Antivir°¡ ³²±â´Â ·Î±×ÀÇ facility´Â local1, priority´Â debug·Î º¯°æÇßÀ¸¹Ç·Î
    syslog.confÀÇ µðÆúÆ® ¼³Á¤À̶ó¸é messages¿¡ ³²±âÁö ¾Ê½À´Ï´Ù.
    syslog.conf ¼³Á¤À» ¼öÁ¤ÇÑ ÀûÀÌ Àִٸ頠
    local1.debug, local1.*, *.debug, *.* µîÀÇ ÁÙÀÌ ÀÖ´ÂÁö È®ÀÎÇغÁ¾ß ÇÕ´Ï´Ù.

    Q8) /var/spool/avmilter/rejected¿¡ ÀÖ´Â df, vf´Â ¹«½¼ ÀǹÌÀΰ¡¿ä?
    -----------------------------------------------------------------------

    A8) rejected¿¡ ÀÖ´Ù´Â °ÍÀº ¹ÙÀÌ·¯½º³ª ¸ÞÀÏ mime ŸÀÔ¿¡ ¹®Á¦°¡ ÀÖ´Ù°í Antivir°¡
    ÆÇ´ÜÀ» ÇÏ°í ¸ÞÀÏ ¼Û¼ö½ÅÀ» °ÅºÎÇÑ °ÍÀ» ¸»ÇÕ´Ï´Ù.

    df = ¸ÞÀÏ ³»¿ëÀÌ ÀÖ´Â data file
    vf = ¸ÞÀϳ»¿¡ ¹ÙÀÌ·¯½º°¡ ¹ß°ßµÆÀ» ³ªÅ¸³»´Â file
    df-ID¿Í vf-ID ½ÖÀ¸·Î ÀÖÁÒ? xxxxx-xxxxxxxx°¡ °°Àº °ÍÀÌ µ¿ÀÏ ¸ÞÀÏ¿¡ ´ëÇÑ °ÍÀÔ´Ï´Ù.

    antivir´Â ÀÌ·± ÇüÅ·Π°ÅºÎ°¡ µÉ ¶§ /etc/avmilter.conf ¼³Á¤¿¡ µû¶ó ¼Û½ÅÀÚ³ª
    ¼ö½ÅÀÚ¿¡ ¸ÞÀϳ»¿¡ ¹ÙÀÌ·¯½º°¡ ¹ß°ßµÆÀ½À» ¾Ë¸²´Ï´Ù.

    /var/spool/avmilter/rejected ¿¡ ½×ÀÎ ¸ÞÀÏÀ» º¸½Ã°í ÇÊ¿ä¾ø´Â ¸ÞÀÏÀ̶ó¸é
    rm -f [dv]f*
    ·Î ¸ðµÎ Áö¿ì¼¼¿ä.

    Q9) /var/spool/avmilter/rejected/ ¿¡ ³Ê¹« ¸¹Àº ¸ÞÀÏÀÌ °É·¯Áý´Ï´Ù.
    -----------------------------------------------------------------------
        
    A9) avq ¸í·É¾î(Á¦ ±Û¿¡¼­´Â /usr/lib/Anivir/avq¿¡ ¼³Ä¡ÇßÀ½)À» ÀÌ¿ëÇؼ­
        Å¥¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ÇÊ¿ä¾ø´Â ¸ÞÀÏÀ̶ó¸é cronÀ» ÅëÇØ Æ¯Á¤½Ã°£¸¶´Ù »èÁ¦Çϼ¼¿ä.

    crontab -e
    Çؼ­ ´ÙÀ½°ú°°ÀÌ ³ÖÀ¸¸é ¸ÅÀÏ »õº® 0½Ã 5 ºÐ¿¡ rejectedµÈ ¸ÞÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.

    5 0 * * * rm -f /var/spool/avmilter/rejected/*

    Q10) ¹ÙÀÌ·¯½º ÆÐÅÏ ¾÷µ¥ÀÌÆ®´Â ¾î¶»°Ô Çϳª¿ä?
    -----------------------------------------------------------------------

    A10) ½©»ó¿¡¼­ Á÷Á¢ÇÑ´Ù¸é ´ÙÀ½°ú °°ÀÌ ½ÇÇàÇÏ¸é µË´Ï´Ù.

    # antivir --update
    AntiVir / Linux Version 2.0.8-8
    Copyright (C) 1994-2003 by H+BEDV Datentechnik GmbH.
    All rights reserved.

    checking for updates

    06.21.00.35 <=> 06.21.00.35 [vdf, loaded]
    06.21.00.01 <=> 06.21.00.01 [engine, running]
    02.00.08.08 <=> 02.00.08.08 [program, running]

    AntiVir is up-to-date

    cron¿¡ ³Ö´Â ¹æ¹ýÀº ¸ÕÀú ¾´ ±Û¿¡ ÀÖÀ¸´Ï ã¾Æº¸¼¼¿ä.

    Q11) ÆÐÅÏ ¾÷µ¥ÀÌÆ® Áß
    sh: /tmp/antivir_20165_1640464374/download/antivir: Çã°¡ °ÅºÎµÊ ¿¡·¯ ¹ß»ý
    -----------------------------------------------------------------------

    A11) /tmp Æ۹̼ÇÀÌ Á¤»óÀ̶ó¸é Àúµµ ¿øÀÎÀº ¸ð¸£°Ú½À´Ï´Ù.

    Àӽ÷Π¼öµ¿ ¾÷µ¥ÀÌÆ® Çϼ¼¿ä.

    http://www.antivir.de/down/vdf/vdf.zip ¸¦ ¹Þ½À´Ï´Ù.
    ÆÄÀÏÀ» Ç®¸é (unzip vdf.zip) ÆÄÀÏ 3°³°¡ ³ª¿Ã°Ì´Ï´Ù.
    ±×Áß¿¡ antivir.vdf ¸¸ /usr/lib/Antivir ·Î º¹»çÇÕ´Ï´Ù. Æ۹̼ÇÀº 644·Î.

    # chmod 644 antivir.vdf
    # mv antivir /usr/lib/Antivir/
      Ä¿ÇǴнº Ä«Æä ÃÖ±Ù ±Û
    [04/25] ±¹°¡&#5
    [04/24] º¸Çè&#5
    [04/22] Re: OpenSSL Ãë¾àÁ¡ Á¤¸®, Logjam(·Î±×Àë)¿¡¼­ Heartbleed±îÁö
    [04/21] LET¡¯S START WITH ON
    [04/21] º¸Çè&#5
    [04/20] Á¦ÁÖ&#5
    [04/20] ±¹³»&#5
    [04/19] Á¦ÁÖ&#5
    [04/18] ??? ?????
    [04/17] ???? onion ?????? -
    [04/11] ±¹°¡&#5
    [04/10] Stride Into Dream:
    [03/20] Re: ¿Â¶óÀΰÔÀÓÀÇ Á¾ÁÖ±¹ ´ëÇѹα¹
    [10/20] Cross Compiler ±ò
    [07/14] SSL ¬¡¬°
      New!   ÃÖ±Ù¿¡ µî·ÏÇÑ ÆäÀÌÁö
      KiCad EDA Suite project (Free/Libre/Open-Source EDA Suite) (CAD)
      ¿ÀÇÂij½ºÄÉÀ̵å ijµå (OpenCASCADE CAD)
      QCad for Windows --- GNU GPL (Free Software)
      The Hello World Collection
      IPMI¸¦ È°¿ëÇÑ ¸®´ª½º ¼­¹ö°ü¸®
      DNS ¼³Á¤ °Ë»ç
      nagiosgraph ¼³Ä¡ ¹æ¹ý
      Slony-I ¼³Ä¡ ¹æ¹ý (postgresql replication tool)
      Qmail±â¹ÝÀÇ Anti spam ½Ã½ºÅÛ ±¸ÃàÇϱâ
      clusterssh

    [ ÇÔ²²ÇÏ´Â »çÀÌÆ® ]




    ¿î¿µÁø : ÁÁÀºÁøÈ£(truefeel), ¾ß¼ö(yasu), ¹ü³ÃÀÌ, sCag
    2003³â 8¿ù 4ÀÏ~